An SSL certificate encrypts the connection between your browser and a website
An SSL certificate is a small file that a website installs on its server to turn on encryption. When you visit a website with an SSL certificate, your browser and that server create an encrypted tunnel — anything you type (passwords, credit card numbers, messages) travels through that tunnel where only your browser and the server can read it. Without SSL, that information travels in plain text that anyone on the network could intercept.
You can tell a website has an SSL certificate by looking at the address bar. If the URL starts with https:// instead of http://, the site is using SSL. You may also see a small padlock icon next to the address. That padlock means your connection to that specific website is encrypted right now.
SSL certificates are issued by certificate authorities — companies like DigiCert, Let's Encrypt, and Sectigo that verify a website owner's identity before handing out a certificate. The certificate contains the website's public encryption key and proof that a trusted authority checked who owns the domain. Your browser uses that proof to confirm it is talking to the real website, not a fake one pretending to be that site.
Key Takeaways
- An SSL certificate encrypts data sent between your browser and a website so that passwords and payment information cannot be read if intercepted.
- You can see whether a site has an SSL certificate by checking whether the URL begins with https:// and whether a padlock appears in the address bar.
- Certificate authorities like Let's Encrypt and DigiCert issue SSL certificates after verifying that the person requesting it actually owns the website's domain.
- An SSL certificate also proves you are connected to the real website and not a fake copy, because browsers trust only certificates issued by known authorities.
How SSL encryption actually works
SSL uses two keys: a public key that the website shares openly and a private key that only the website's server knows. When your browser connects, the server sends its public key. Your browser uses that public key to encrypt your data before sending it. Only the server's private key can decrypt it — so even if someone intercepts the encrypted message, they cannot read it without the private key.
This happens automatically every time you load an https:// page. You do not have to do anything. Your browser handles the encryption and decryption in the background so fast you never notice it is happening.
The difference between http and https
The only difference between http:// and https:// is the "s" — which stands for "secure." An http:// site has no encryption. Everything you type goes across the internet in plain text. An https:// site has encryption turned on by an SSL certificate.
Most modern websites use https:// by default, even for pages where you are not entering sensitive information. Banks, email services, and shopping sites absolutely require it. But even a blog or news site should have https:// because it protects your privacy — it stops your internet provider or anyone else on the network from seeing which articles you read or what you search for on that site.
What certificate authorities do
A certificate authority is a company that issues SSL certificates. Before issuing one, the authority verifies that the person requesting the certificate actually owns or controls the website's domain. This verification step is what makes the certificate trustworthy.
Different certificate authorities do different levels of checking. A basic check might be automated — the authority sends an email to the domain owner's registered address and asks them to click a link. A more thorough check, called an extended validation certificate, involves a human reviewer who calls the business and checks public records to confirm the company is real. Extended validation certificates cost more but provide stronger proof of identity.
Let's Encrypt is a free certificate authority run by a nonprofit. It issues basic SSL certificates after automated verification. Paid authorities like DigiCert and Sectigo offer faster issuance, longer validity periods, and higher levels of identity verification if a business needs it.
Why your browser trusts some certificates and not others
Your browser comes with a built-in list of certificate authorities it trusts. When you visit an https:// website, your browser checks whether the SSL certificate was issued by one of those trusted authorities. If it was, the browser shows the padlock and lets you proceed. If the certificate was issued by an authority the browser does not recognize, or if the certificate has expired, the browser shows a warning.
This system prevents fake websites from tricking you. A scammer could create a fake copy of your bank's website, but they cannot get a valid SSL certificate for it because the certificate authority will not issue one to someone who does not own the domain. If they try to use a fake or self-signed certificate, your browser will warn you that something is wrong.
How long SSL certificates last
SSL certificates expire. Most last one year, though some last two or three years. When a certificate is about to expire, the website owner must renew it by requesting a new certificate from the certificate authority. The renewal process is usually quick — often just a few clicks if the authority already verified the domain before.
If a website's SSL certificate expires and is not renewed, the browser will show a warning that the connection is not secure. The site will still load, but the warning tells you the encryption is no longer valid. This rarely happens because website owners get reminder emails before expiration, and renewal is usually automatic.
Self-signed certificates and why they show warnings
A website owner can create their own SSL certificate without going through a certificate authority — this is called a self-signed certificate. The encryption still works technically, but your browser does not trust it because no recognized authority verified the domain owner's identity.
When you visit a site with a self-signed certificate, your browser shows a warning like "Your connection is not private" or "This site's security certificate is not trusted." This warning exists to protect you from fake websites. A legitimate business will always use a certificate from a trusted authority, not a self-signed one. If you see this warning on a site you expected to be secure, it is a sign something is wrong.
Frequently Asked Questions
Does an SSL certificate mean a website is safe?
No. An SSL certificate only means the connection between you and the website is encrypted. It does not mean the website is legitimate, that it will not steal your information, or that it is free of malware. A scam website can have a valid SSL certificate. Always check the domain name carefully and use other signals like reviews and official links to confirm you are on the real site.
Can I see what information is encrypted?
No. Encryption means that even if someone intercepts the data traveling between your browser and the server, they cannot read it. The encryption happens automatically — you cannot see it or control it. Your browser and the server handle all the encryption work behind the scenes.
What happens if a website does not have an SSL certificate?
If a website uses http:// instead of https://, your data travels unencrypted. Anyone on the same network — your internet provider, your employer's network, or someone using the same public WiFi — could potentially see what you type, including passwords and payment information. You should never enter sensitive information on an http:// site.
Do I need to pay for an SSL certificate on my own website?
Not necessarily. Let's Encrypt offers free SSL certificates for any domain. Many web hosting companies include free SSL certificates with their plans. Paid certificates from other authorities cost between $50 and $300 per year, usually only if you need extended validation or other advanced features.
Can someone steal my password even if the site has SSL?
SSL protects your password while it travels to the website, but not after. If the website itself is hacked or if you use the same password everywhere, your password can still be compromised. SSL only encrypts the connection — it does not make the website itself secure. Use unique, strong passwords and enable two-factor verification when available.